An off-by-one error in function wavreadheader in src/wav.c in Libsndfile 1.1.0 results in a write out of bound which allows an attacker to execute arbitrary code Denial of Service or other unspecified impacts.
Libsndfile <=1.2.2 contains a memory leak vulnerability in the mpegl3encoderinit() function within the mpegl3encode.c file.